Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified SOC Analyst

Domain 6Objective 1

Incident Response Process CSA Practice Questions (Page 6)

Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.

56questions here
12free pages
9concepts

Questions 26–30

  1. 26foundation · easy

    Which section should be included in an incident report to provide a chronological account of the incident?

    Select an answer first
  2. 27foundation · easy

    What is the primary purpose of maintaining a chain of custody for digital evidence?

    Select an answer first
  3. 28application · medium

    A SOC analyst is investigating a possible data breach. The analyst has logs from the firewall, the authentication server, and the file server. Which correlation would most strongly indicate a data breach?

    Select an answer first
  4. 29foundation · easy

    After an incident has been contained and eradicated, what is the primary goal of the recovery phase?

    Select an answer first
  5. 30application · medium

    A company has confirmed a ransomware infection on a file server. The malware is actively encrypting files. The incident response team needs to stop the spread while preserving evidence. Which containment action should be taken FIRST?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.